--- # radosgw admin credentials for local testing. Replace the values, or create the # Secret out-of-band, before applying. Keys map 1:1 to the operator env vars. # The access/secret key belong to an RGW user with admin caps # (users=*, buckets=*, metadata=read). apiVersion: v1 kind: Secret metadata: name: cephrgw-credentials namespace: cephrgw-system type: Opaque stringData: # radosgw endpoint the operator talks to (Admin Ops + S3 APIs). CEPH_RGW_ADMIN_ENDPOINT: "https://radosgw.service.consul:443" CEPH_RGW_ACCESS_KEY: "change-me" CEPH_RGW_SECRET_KEY: "change-me" # The S3 endpoint written into credential Secrets for consumers (may be a # public name that differs from the API endpoint above). CEPH_RGW_ENDPOINT: "https://s3.ceph.unkin.net" # Optional: SigV4 credential-scope region (defaults to "default"). # CEPH_RGW_REGION: "default" # Optional: set to "true" to skip TLS verification (dev only). # CEPH_RGW_INSECURE: "true" --- apiVersion: apps/v1 kind: Deployment metadata: name: cephrgw-operator namespace: cephrgw-system labels: app.kubernetes.io/name: cephrgw-operator spec: replicas: 1 selector: matchLabels: app.kubernetes.io/name: cephrgw-operator template: metadata: labels: app.kubernetes.io/name: cephrgw-operator spec: serviceAccountName: cephrgw-operator securityContext: runAsNonRoot: true containers: - name: operator image: cephrgw-operator:dev imagePullPolicy: IfNotPresent args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 - --leader-elect envFrom: - secretRef: name: cephrgw-credentials ports: - containerPort: 8080 name: metrics - containerPort: 8081 name: health readinessProbe: httpGet: path: /readyz port: 8081 livenessProbe: httpGet: path: /healthz port: 8081 securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: ["ALL"] resources: requests: cpu: 50m memory: 64Mi limits: cpu: 500m memory: 256Mi